Contrôle des accès avec IAM

Google Cloud Fraud Defense propose un contrôle des accès basé sur les rôles (RBAC) avec Identity and Access Management (IAM) et un contrôle des accès pour l'API reCAPTCHA Enterprise à l'aide de VPC Service Controls.

Contrôle des accès basé sur les rôles avec IAM

IAM vous permet d'accorder un accès précis à des ressources spécifiques Google Cloud et empêche tout accès non souhaité à d'autres ressources, telles que les journaux et les analyses.

Cette section décrit les rôles IAM pour Fraud Defense.

Pour savoir comment attribuer des rôles IAM à un compte utilisateur ou de service, consultez Accorder, modifier et révoquer les accès à des ressources dans la documentation IAM.

Rôles et autorisations

Le tableau suivant répertorie les rôles IAM nécessaires et leurs autorisations pour Fraud Defense :

Role Permissions

(roles/recaptchaenterprise.admin)

Access to view and modify reCAPTCHA Enterprise keys

monitoring.timeSeries.list

recaptchaenterprise.firewallpolicies.*

  • recaptchaenterprise.firewallpolicies.create
  • recaptchaenterprise.firewallpolicies.delete
  • recaptchaenterprise.firewallpolicies.get
  • recaptchaenterprise.firewallpolicies.list
  • recaptchaenterprise.firewallpolicies.update

recaptchaenterprise.keys.*

  • recaptchaenterprise.keys.create
  • recaptchaenterprise.keys.createTagBinding
  • recaptchaenterprise.keys.delete
  • recaptchaenterprise.keys.deleteTagBinding
  • recaptchaenterprise.keys.get
  • recaptchaenterprise.keys.list
  • recaptchaenterprise.keys.listEffectiveTags
  • recaptchaenterprise.keys.listTagBindings
  • recaptchaenterprise.keys.retrievelegacysecretkey
  • recaptchaenterprise.keys.update

recaptchaenterprise.metrics.get

recaptchaenterprise.projectmetadata.*

  • recaptchaenterprise.projectmetadata.get
  • recaptchaenterprise.projectmetadata.update

resourcemanager.projects.get

resourcemanager.projects.list

(roles/recaptchaenterprise.editor)

Editor role for recaptchaenterprise

monitoring.timeSeries.list

recaptchaenterprise.assessments.*

  • recaptchaenterprise.assessments.annotate
  • recaptchaenterprise.assessments.create

recaptchaenterprise.firewallpolicies.*

  • recaptchaenterprise.firewallpolicies.create
  • recaptchaenterprise.firewallpolicies.delete
  • recaptchaenterprise.firewallpolicies.get
  • recaptchaenterprise.firewallpolicies.list
  • recaptchaenterprise.firewallpolicies.update

recaptchaenterprise.keys.create

recaptchaenterprise.keys.delete

recaptchaenterprise.keys.get

recaptchaenterprise.keys.list

recaptchaenterprise.keys.listEffectiveTags

recaptchaenterprise.keys.listTagBindings

recaptchaenterprise.keys.retrievelegacysecretkey

recaptchaenterprise.keys.update

recaptchaenterprise.metrics.get

recaptchaenterprise.projectmetadata.*

  • recaptchaenterprise.projectmetadata.get
  • recaptchaenterprise.projectmetadata.update

recaptchaenterprise.relatedaccountgroupmemberships.list

recaptchaenterprise.relatedaccountgroups.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/recaptchaenterprise.viewer)

Access to view reCAPTCHA Enterprise keys and metrics

monitoring.timeSeries.list

recaptchaenterprise.firewallpolicies.get

recaptchaenterprise.firewallpolicies.list

recaptchaenterprise.keys.get

recaptchaenterprise.keys.list

recaptchaenterprise.keys.listEffectiveTags

recaptchaenterprise.keys.listTagBindings

recaptchaenterprise.metrics.get

recaptchaenterprise.projectmetadata.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/recaptchaenterprise.agent)

Access to create and annotate reCAPTCHA Enterprise assessments

recaptchaenterprise.assessments.*

  • recaptchaenterprise.assessments.annotate
  • recaptchaenterprise.assessments.create

recaptchaenterprise.firewallpolicies.list

recaptchaenterprise.relatedaccountgroupmemberships.list

recaptchaenterprise.relatedaccountgroups.list

resourcemanager.projects.get

resourcemanager.projects.list

Rôles personnalisés

Vous pouvez avoir besoin de rôles personnalisés pour des cas d'utilisation tels que les exigences réglementaires. Pour créer un rôle personnalisé incluant des autorisations Fraud Defense, effectuez l'action appropriée, comme indiqué dans le tableau suivant :

Description du rôle Action
Rôle n'accordant des autorisations que pour l'API reCAPTCHA Enterprise Sélectionnez l'une des autorisations dans la section Autorisations des API.
Rôle accordant des autorisations pour l'API et la console reCAPTCHA Enterprise Choisissez des groupes d'autorisations dans la section Rôles et autorisations.
Rôle permettant de créer et d'annoter des évaluations Incluez les autorisations du rôle roles/recaptchaenterprise.agent dans la section Rôles et autorisations.

Pour en savoir plus sur les rôles personnalisés, consultez la page Créer et gérer les rôles personnalisés.

Autorisations des API

Le tableau suivant répertorie les autorisations que l'appelant doit avoir pour appeler chaque méthode dans l'API reCAPTCHA Enterprise, recaptchaenterprise.googleapis.com/v1 :

Méthode (REST/RPC) Autorisations requises Type de ressource concerné
recaptchaenterprise.assessments.annotate / AnnotateAssessmentRequest recaptchaenterprise.assessments.annotate projet
recaptchaenterprise.assessments.create / CreateAssessmentRequest recaptchaenterprise.assessments.create projet
recaptchaenterprise.keys.create / CreateKeyRequest recaptchaenterprise.keys.create projet
recaptchaenterprise.keys.delete / DeleteKeyRequest recaptchaenterprise.keys.delete projet
recaptchaenterprise.keys.get / GetKeyRequest recaptchaenterprise.keys.get projet
recaptchaenterprise.keys.list / ListKeysRequest recaptchaenterprise.keys.list projet
recaptchaenterprise.keys.update / UpdateKeyRequest recaptchaenterprise.keys.update projet

VPC Service Controls

VPC Service Controls est compatible avec Fraud Defense pour fournir un contrôle des accès supplémentaire pour les API reCAPTCHA. Pour en savoir plus, consultez la page Produits compatibles et limites  > Fraud Defense.